If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS
If you don't like CF just switch to different provider https://github.com/curl/curl/wiki/DNS-over-HTTPS
I trust my ISP and government more than a US company I have no formal contract with and the US government.
Also, there's the whole 'applications should not override system level settings' thing. My DHCP pushes a local (caching) DNS server that also does name resolution for internal services. This change would break that for all Firefox users on my network.
And every single intermediary and whoever else might be listening in? This is an unencrypted plaintext connection. Which is the main point here. The whole "we trust ISP more" thing is completely beside the point. The point is DNS is horribly insecure nowadays, and it is about damn time we switch to something better.
> Also, there's the whole 'applications should not override system level settings' thing.
Hopefully, DoH will become a system level setting eventually.
The only thing the snooper won't be sure with is, which Cloudflare client asked for that record.
Thus, Cloudflare is the problematic intermediary.
You're not affected then, because the DoH rollout w/ Cloudflare as the default is only planned for the US.
I wish Windows 10 and other operating systems natively supported DNS-over-HTTPS, but many don't. So they have to work around that lack of support.
https://www.ghacks.net/2018/04/02/configure-dns-over-https-i...
I use https://odvr.nic.cz/doh
Because if you do, at that point they are your "ISP" for purposes of this discussion. Do you still trust them more than Cloudflare?
(For a desktop machine, obviously this is not an issue, but for pretty much anyone with a laptop this is something that needs to be worried about.)
As far as internal services, is this a split-horizon setup? As far as I understand, the plan is to detect those and fall back from DoH to normal DNS as needed.
I do not! I'd rather have that anon US co. than any government.
For now.
I feel like at least in Europe, a large majority of people would trust their government and local ISP much more than some company halfway over the world with basically no accountancy in your own country, especially an American one since it means your data is basically at the mercy of the US government.
Seems like this is a very good move for them.
I still trust my DNS servers (or those of most ISPs, for that matter) more than I trust Cloudflare. I'd rather have intelligence services go through the effort of infiltrating every single ISP separately to get any useful dragnet intelligence, instead of just one large entity that can illegally collect all traffic from all users of a web browser.
And I very much hope they aren't contemplating rolling this out in Europe.
Having worked for a major European telco, I get the impression that the amount of regulation they face around data protection and privacy is tremendous and my experience has been that this stuff is by no means taken lightly either.
It would never in a million years occur to me to route my traffic in such a way as to circumvent the legal protections it enjoys as long as it stays within a European ISP's network and instead encrypt it and send it off to a nearly unregulated entity in a foreign country.
> https://support.mozilla.org/en-US/kb/firefox-dns-over-https
Mozilla has a strong Trusted Recursive Resolver (TRR) policy in place that forbids CloudFlare or any other DoH partner from collecting personal identifying information. To mitigate this risk, our partners are contractually bound to adhere to this policy.
These are much stronger guarantees than my ISP's.
Your ISP has access to more detailed data on you than DNS queries. Also CF servers are typically located in the same jurisdiction as your government and send unencrypted DNS queries from there. Now instead of dealing with every ISP your government has to deal with just one company in one location, no need to even ask that company anything, just come in and setup mirroring point, very convenient for the government, not very good for you.
Even with DoH, my ISP already sees all of my network traffic. My DNS queries will effectively be anonymized by their recursive name servers.
I believe the GP comment was referring to government surveillance. This is a thing in Europe and GDPR won't protect you from it.
Also, good news for you: Since you live in Europe, the announced switch to DoH with Cloudflare as the default for Firefox users in the US won't affect you.